Zapier · AI by Zapier

AI by Zapier agentic tool execution

When configured with tools, the AI by Zapier step reasons over a task, chooses among configured tools, determines tool field values at runtime where the builder permits, and invokes those tools from within the AI step. Documented app-action examples include looking up a CRM record, sending a Slack message and adding a spreadsheet row. Excludes deterministic Zap steps before or after the AI step, prompt-only generation, legacy standalone Zapier Agents as a separate capability, Zapier MCP and Next Gen Zaps Agentic Management.

Recorded characteristics

Function
Zapier documents that tools can be added to an AI by Zapier step "to allow it to use other apps to complete your prompt"; with tools, it "uses multiple tools to gather information and produce a result, rather than just generating a completion". Tool types: App action ("Use any Zapier app and action as a tool, such as looking up a record in your CRM, sending a Slack message, or adding a row to a spreadsheet"), Knowledge sources and a Browse the web toggle. Adding a tool "lets AI by Zapier decide when and how many times to call each tool based on your prompt", and "AI by Zapier only uses the tools it needs". For each tool input field the builder chooses: Set specific field (static or mapped value), Let agent choose from list, Agent determines field (value determined at runtime from the prompt), or Exclude field. The preview's "Tools used" panel lists each tool called, what it did and whether it succeeded; Zap history records which tools were called and what data was passed. Zapier states migration from Agents "does not split your tool calls into separate native Zap steps. Your tools continue to run inside the AI step". Tools are optional: without them the step runs prompt-only, which is excluded from this capability. Web browsing and knowledge retrieval are not treated as persistent external action. Not every Zapier app action is established as tool-compatible beyond Zapier's statement that any app and action can be used as a tool; no specific delete example is recorded.
Data access
Determined by the configured tools and the connected app accounts selected for them, plus any knowledge sources and web browsing enabled. Zapier states app connections grant access only to data authorised for the connected account. No data scope beyond configured tools is attributed.
Actions
Can take actions
External actions
Yes
Human confirmation
Conditional
Permission basis
Separate permissions
Administrative control
Per-tool approval: when adding or editing a tool, "Require approval before running" pauses the run and asks for approval before AI by Zapier uses that tool. It is off by default ("the tool runs without interruption unless you turn it on"); tools without it run without interruption. When enabled, approval applies "regardless of how the prompt is worded". Zapier recommends enabling it for tools that create, update or delete data. No class of action is documented as requiring approval regardless of configuration. Separate, not runtime action confirmation: pauses when more information is needed, the 75-task per-run pause, admin approval flows before publishing Zaps containing AI steps, and Human in the Loop steps elsewhere in a Zap. Account controls: Zapier's migration guide states admins "can enable or disable tool calling and agentic behavior at the account level from the Admin Control Center", and organisations that previously had Agents blocked have tool calling off by default. Admins can restrict available models, and Enterprise app access settings (restricted or allowed apps) control which apps members can use. Triggers: the step runs inside ordinary Zaps started by any supported Zap trigger (for example schedule, webhook or app events) and can execute unattended after publication; trigger differences are kept within this capability.
Default state
Conditional
Availability
Actions require configuration: a Zap with an AI by Zapier step, a model tier that supports tools (Advanced or Premium, or Bring Your Own Key with an Advanced or Premium model; Standard does not support tools), tools deliberately added, and a connected account selected for each app-action tool, followed by publishing the Zap. Tool calling may be disabled at account level. Zapier's migration guide states AI by Zapier with looping tool calls became generally available on July 15, 2026. Migration context: Zapier is migrating standalone Agents (agents.zapier.com) to AI by Zapier; each converted agent becomes a Zap with a native trigger and one AI by Zapier step containing the original prompt, instructions and tools, and users are prompted to turn off the original agent. Enterprise trial accounts had until August 15, 2026 to migrate, then converted to free Agents accounts. A final shutdown date for standalone Agents, and whether new standalone Agents can still be created, are not established.
Licensing
Plan information conflicts across first-party pages: the Add tools article lists Free, Professional, Team and Enterprise; the June 15, 2026 pricing notice says Professional, Team and Enterprise with tool calls on Advanced or Premium tiers; other AI by Zapier pages list Enterprise. On Free, AI by Zapier can be previewed in an unpublished Zap on the Standard tier only (no tools). Usage is task-based by model tier (Standard 1x, Advanced 3x, Premium 5x, Bring Your Own Key 1x), with tool calls adding tasks. No single universal plan statement is recorded.
External model or provider
No single model or provider. Model selection is configurable by tier or specific model, including OpenAI, Anthropic and Google models, and Bring Your Own Key provider accounts (OpenAI, Anthropic, Google Gemini, Azure OpenAI, Amazon Bedrock). Zapier currently documents Auto as Claude 4.5 Haiku for Advanced and Claude 4.6 Sonnet for Premium; this is current default behaviour, not a fixed model for the capability. Admins can restrict available models. The default tier is documented inconsistently (Premium in the Add tools and pricing pages; Advanced in the June 15, 2026 pricing notice).
Limitations and uncertainty
Permission basis is recorded as separate_permissions: app-action tools execute using the stored Zapier app connection selected in the tool's Account field. Zapier documents that a connection links to a single user account and grants Zapier read and write access to data authorised for that account (OAuth 2.0, API key, basic, session or digest authentication). Connections can be shared so other Zapier users can use them without the underlying login credentials; sharing does not by itself make the record mixed. Execution is not established as bound to whichever human triggers the Zap (not user_permissions), and no independent agent identity is documented (not dedicated_agent_identity). Unresolved: what a reviewer sees before approving a tool call (including proposed field values); whether an explicit Reject control exists; dedicated documentation for the account-level tool-calling switch (currently stated only in the migration guide); final shutdown date for standalone Zapier Agents; whether new standalone Agents can still be created; plan availability contradictions; default model-tier contradiction; explicit delete-action examples. Excluded: deterministic Zap steps, legacy standalone Agents as a separate capability, Zapier MCP, Next Gen Zaps Agentic Management, prompt-only output, Human in the Loop steps, Zap publication approval, missing-information and 75-task pauses.

Evidence